Application Number: AU 2026202109

Wearing a Believable Disguise Online AI-Built Artificial Profiles That Control What Your Computer Reveals

The system builds what the specification calls an artificial profile model. It identifies the set of data privacy elements a device can leak, evaluates them using [machine learning](https://en.wikipedia.org/wiki/Machine_learning) techniques, and derives constraints, rules that capture the dependencies between elements, which combinations of attributes plausibly occur together on a real machine. The model can also include

Open for Public Inspection
AU 2026202109 Featured Image

View the Wearing a Believable Disguise Online PDF

Download the PDF version of this Application Open to Public Inspection

This application covers a data protection platform that uses artificial-intelligence-based modelling to control what a computer exposes about itself online. Instead of simply hiding identifying details, the system generates artificial profiles, coherent fake identities for the device, and even masks the way a user types before anyone on the other end can collect it. The applicant is Grey Market Labs, a Virginia public benefit corporation founded by veterans of the US intelligence community, which now operates as Replica Cyber.

The Problem

The background section starts from an uncomfortable fact: every computing device connected to the Internet produces exposable data. When a laptop connects to a web server, the server can query the browser for information, the operating system, browser version, language, time zone, screen size and more. Collected together, these details form a device fingerprint that can identify a machine, and by extension the person using it, without any cookie or login.

That exposure cuts both ways. Authorised hosts such as websites use it routinely, but an unauthorised host, a hacker, can exploit the same information to find vulnerabilities and execute a data breach. The specification notes that near-constant use of computing devices and the Internet keeps increasing both the complexity and the privacy risk of this exposable data.

There is also a subtler failure mode the invention is built around: naive spoofing does not work. Change one attribute in isolation, claim a different browser while keeping the old fonts and plugins, and the inconsistency itself becomes a signature. A convincing disguise has to be internally consistent.

What This Invention Does

The system builds what the specification calls an artificial profile model. It identifies the set of data privacy elements a device can leak, evaluates them using machine learning techniques, and derives constraints, rules that capture the dependencies between elements, which combinations of attributes plausibly occur together on a real machine. The model can also include attribution vectors, representations of the detectable characteristics that make a device recognisable.

When a device requests access to a network location, the platform detects which data privacy elements are about to be exposed, determines the profile the device currently presents, and automatically modifies those elements according to the model’s constraints. The result is a new artificial profile: a fake but believable identity that masks the device from being identified, while remaining consistent enough not to raise flags. Profiles can be refreshed on later requests, so the device never presents a stable identity to track.

Claim 1 of this divisional pushes into more personal territory. It is directed at masking an input signature, the pattern that characterises input received at a platform-secured browser, in effect the user’s typing rhythm and interaction style, the domain known as keystroke dynamics. When the user submits input bound for a remote server that sits behind a gateway run by a data-collecting network host, the platform dynamically modifies the relevant data privacy elements and generates a masked input signature, using a constraint from the artificial profile model, before the host ever collects the data. The masked signature is folded into a new artificial profile and transmitted, so the network host is prevented from accurately profiling the input. Parallel claims cover the system and the computer program product forms of the same idea.

Key Features

  • Artificial profile model. A machine-built model of exposable data privacy elements, including constraints for generating new artificial profiles that a real-world device could plausibly present.
  • Constraints keep the lie consistent. Constraints represent dependencies between data privacy elements, so modified attributes stay coherent with each other instead of creating a suspicious mismatch.
  • Masking before collection. Data privacy elements, including the input signature, are modified before the network host collects them, not scrubbed after the fact.
  • Typing rhythm disguise. The claimed method masks the signature characterising input at a platform-secured browser, blunting behavioural biometrics as a tracking channel.
  • Profiles that keep changing. New artificial profiles can be generated as the device makes further requests, denying trackers a stable identity across sessions.
  • Selective exposure control. Modification can include preventing elements from being exposed at all, giving the platform a dial between disclosure, disguise and silence.

Who Is Behind It

Grey Market Labs, PBC is a public benefit corporation and certified B Corp based in the Washington DC area, founded to protect digital life. Its founders came from the US intelligence community and consulting, where conducting high-stakes online work without exposing people or missions was a daily problem. The company commercialised that experience as the Replica platform, secure environments as a service built on a zero trust approach, and in 2025 rebranded the business as Replica Cyber.

Two inventors are named: Timothy Ryan Underwood and Kristopher Paul Schroeder. Schroeder is the company’s co-founder and chief executive, previously a principal at Booz Allen Hamilton; Underwood, who goes by Ryan, is co-founder and chief technology officer.

The priority chain runs deep for a software patent. This application is a divisional of Australian application 2024204413, filed 27 June 2024, itself a divisional of 2019287571, which entered the Australian national phase on 14 October 2020 from PCT/US2019/014143, filed 18 January 2019 and claiming the benefit of US application 16/005,268, filed 11 June 2018.

Why It Matters

Browser fingerprinting has become the tracking industry’s answer to the death of the third-party cookie, and the same techniques serve hostile reconnaissance. Conventional defences, VPNs, private browsing, fingerprint blockers, mostly subtract information, and an absence of information is itself distinctive. The approach claimed here is different in kind: fabricate a complete, internally consistent alternative identity, and keep fabricating fresh ones. That is the difference between hiding and wearing a disguise.

The move in this divisional to claim input signature masking is worth noting. Behavioural biometrics, identifying users by how they type and move a mouse, is spreading through fraud detection and authentication systems, which makes it a tracking vector that survives even a perfect device disguise. A claim that reaches masking of typing patterns at the browser extends the family from what a machine says about itself to what a human does on it.

Three generations of Australian divisionals from a 2018 US priority show an applicant keeping claim scope flexible while the market for secure enclaves and managed attribution matures, a strategy more often seen from pharmaceutical companies than from a security startup.

Related Concepts


AU 2026202109 was published in the Australian Official Journal of Patents on 9 April 2026 and is open for public inspection. Patent applications represent inventions that are sought to be protected and do not necessarily reflect commercially available products.

Related Patents Open to Public Inspections

See related Patents open to public inspection.

Open for Public Inspection

Tamper-Proof at Boot

Application Number: AU 2026201520 Filed:27/02/26 | Published: 19/03/26
Disclaimer

The information presented in this article is provided for general informational and illustrative purposes only.

Content on this page may be derived from publicly available intellectual property records, including patent documentation and related materials. While reasonable care is taken in compiling and summarising this information, ATMOSS does not guarantee the accuracy, completeness, currency, or reliability of any content presented.

This article is not a substitute for reviewing the original source documents. Patent applications, specifications, claims, and related records may contain detailed technical, legal, and contextual information that is not fully represented in this summary.


ATMOSS does not provide legal, technical, or commercial advice. Users should not rely on this content for decision-making purposes.
For authoritative and up-to-date information, users should refer directly to the official records available via IP Australia and other relevant intellectual property databases. Links to these official sources are provided where applicable.


ATMOSS accepts no liability for any loss, damage, or consequences arising from the use of, or reliance on, the information contained in this article.